What Divebase collects, where it goes, and what you can do about it.
Divebase is a dive logbook. Your dive log is yours: we do not sell it, we do not show advertising against it, and we do not track you across other apps or websites.
Last updated: 2026-08-27
For any question about this policy, or to exercise any right described below, write to hello@divebase.cloud.
What this policy covers
This one policy covers every part of Divebase:
- the website at
divebase.cloud - the web application at
app.divebase.cloud, including the API atapi.divebase.cloud - the Divebase app for iOS
- the Divebase app for Android
Where the parts behave differently, this policy says so. It does not cover a service someone else runs that you reach from Divebase, such as the App Store, Google Play, or a linked website.
The mobile apps
Both apps keep your logbook in a database on your own device. You can use either app without an account, without a network connection, and without sending anything to us.
The apps talk to your dive computer over Bluetooth to download your dives. That conversation happens entirely on your device; the download itself sends nothing to us.
The apps read your location only when you ask for it. In both apps, the locate control on the dive site map centres the map on you. In the iOS app, you can also place a dive site at your current position, which saves that coordinate into your logbook. Neither app follows your location in the background.
The map is drawn by Google Maps on Android and by Apple Maps on iOS. When the map draws, that provider receives the map requests it needs to draw it, under its own privacy policy. We do not send your logbook to either of them.
Sync is off until you turn it on. When you connect an account by entering an API token, the app sends your logbook to Divebase, including the dives you downloaded from your dive computer, and reads back what your account already holds. If you never connect an account, your logbook never leaves the device.
The iOS app reports crashes and unexpected sync failures to Sentry so we can fix them. The reports are not tied to your account. The Android app sends no crash reports.
On Android, the system backup service can copy the app's data to your Google account, under Google's own policy. The sync credentials are excluded from that backup.
Neither app shows advertising, and neither contains an analytics or tracking library.
The account and the web application
If you create a Divebase account, we store:
- your email address, and your password as a hash we cannot reverse
- your diver profile: the name, contact, and medical details, such as a blood group, that you choose to put on it
- your dive log: dives, dive sites, dive profiles, gases, cylinders, equipment, certifications, buddies, insurances, trips, and tags
- any file you upload, such as a certification card image or a logbook file you import
- the API tokens you create so an app can sync
- your sign-in sessions, each recording the IP address and browser it was created from
We use this to run the service for you. We do not use your dive log to build a profile of you, and we do not share it with anyone except the providers listed below, who process it on our behalf so that the service works.
Your dive log is private to your account unless you deliberately share something. Where Divebase offers a way to publish or share a record, that is an action you take, and it is described where you take it.
The maps in the web application are drawn with tiles from CARTO and satellite imagery from Esri. As with the maps in the apps, those providers receive the map requests needed to draw the map, not your logbook.
The website
The website and the web application use Fathom Analytics to count visits. Fathom sets no cookies, does not identify individual visitors, and does not follow you to other websites.
We use Sentry to record application errors so we can fix them. An error report can include the request that caused the error, including your IP address.
We send email only for the service itself, such as resetting your password. We do not send marketing email.
Who else processes your data
We use these providers to run Divebase. Each one processes data only to provide its service to us:
- Railway (Europe) — hosting and the database
- Amazon Web Services (S3) — file storage
- Fathom Analytics — visit counts, aggregate only
- Sentry — error and crash reports
- CARTO and Esri — the map tiles and satellite imagery in the web application
- jsDelivr and esm.sh — content delivery networks that serve the web application's JavaScript
Apple and Google also receive information when you download or pay for an app through their stores, and when a map draws. That processing is theirs, under their own policies, and we do not control it.
Your rights
If you are in the European Union or the United Kingdom, the GDPR gives you the right to see the data we hold about you, correct it, delete it, receive it in a portable form, and object to how we use it.
Much of this you can do yourself. You can read and edit every record in your logbook, delete any record, or delete your whole dive log at once. For anything the product does not give you directly, such as a portable export or the deletion of the account itself, write to hello@divebase.cloud. You also have the right to complain to your national data protection authority.
How long we keep things
We keep your account data for as long as your account exists. When you ask us to delete your account, we delete your data within 24 hours, except where a legal obligation requires us to keep a record for longer.
Aggregate analytics counts carry no identity and are kept indefinitely.
Data outside Europe
Some of the providers above operate outside the European Economic Area. Where data reaches them, the transfer relies on the safeguards that provider offers, such as the European Commission's Standard Contractual Clauses.
Changes to this policy
We update this policy when Divebase changes. The date at the top says when it last changed. When you use Divebase, you accept this policy as it stands at that time. If a change materially affects how we handle your data, we may notify you in advance.